Skip to main content
This MCP is a remote Model Context Protocol server hosted by Codemod. It lets AI assistants search your code, track migration progress, find codemods, and start migrations, using the repositories and data in your Codemod account. Each tool runs as you. It applies the same permissions, organization roles, and rate limits as the Codemod app.
This page covers the hosted server at https://app.codemod.com/api/v1/mcp. To give your coding agent tools for building and testing codemods locally, see Codemod MCP (CLI).

What you can do

Once connected, you can ask your assistant things like:
  • “Which of our repositories still use the deprecated fetchUser function? Show me the files.”
  • “Track how many moment imports we have left across our codebase over time.”
  • “Find a codemod for the React 19 upgrade and start the migration for acme/web.”

Prerequisites

  • A Codemod account with access to the organization you want to use
  • An MCP client that supports remote (HTTP) servers and OAuth sign-in, such as Claude or Cursor

Connect your client

1

Add the server

The quickest way is add-mcp, which adds the server to the coding agents it detects, such as Claude Code, Cursor, Codex, and VS Code:
add-mcp asks which agents to configure. Add -g to install for all your projects instead of only the current one.To add the server yourself, use https://app.codemod.com/api/v1/mcp as a remote MCP server in your client:
2

Sign in

Your client opens a browser window. Sign in to Codemod if you aren’t already.
3

Approve access

The consent screen lists the scopes the client is requesting. Review them and select Allow.
4

Verify the connection

Ask your assistant “List my Codemod organizations.” It calls organizations_get_user_organizations and returns the organizations you belong to.
The server registers clients with Client ID Metadata Documents (CIMD). It does not support dynamic client registration. Use a current version of your MCP client.

Scopes

Access tokens are limited to the scopes you approve. Each tool requires one scope, so you can approve read access only. If a client calls a tool outside its granted scopes, the server responds with insufficient_scope and the client asks you to approve the missing scope.

Available tools

Tool names follow the pattern <area>_<action>. Tools with a :read scope don’t change your data, except where noted. Tools marked Requires approval never run without your confirmation. Tools marked Asks first when supported ask for your confirmation only if your client can show a prompt, and otherwise run without one. See Approvals.

Insights

Repositories and code

Grep

These tools use the same indexed repositories as Grep.

Registry

Campaigns

Organizations and automations

insights_dashboard_preview_widget and global_code_check_index are not marked read-only, because they can start widget computations or indexing jobs.

Approvals

Some tools change data or start long-running work. The server asks you to confirm them through MCP elicitation, so your client shows a prompt with the tool name and its arguments. Whether a tool can run without that prompt depends on the tool:
  • Requires approval: project_create_from_package and grep_index_repository run only if you accept. If your client can’t show the prompt, the server refuses the call.
  • Asks first when supported: dashboard create, update, and promote, and grep_create_insights_dashboard, ask when your client can show the prompt and run only if you accept. If your client can’t, they run without asking.
If you decline or cancel a prompt, nothing changes.
If you want a confirmation before any dashboard is created or changed, use a client that supports MCP elicitation, or approve only the read scopes (insights:read, grep:read) when you connect.
A confirmation prompt is not a permission boundary. Token scopes and your organization role decide what a tool can do. Approve only the scopes you want the assistant to use.

Permissions and security

  • Organization roles apply. A tool succeeds only if your role in the organization allows the action. For example, creating a campaign requires the campaign:create role.
  • Tokens are scoped to this server. Access tokens are issued for https://app.codemod.com/api/v1/mcp and are rejected by other Codemod API routes.
  • Organization context comes from your sign-in. The server uses the organization you were signed into when you approved the connection.
  • Updates are conflict-checked. insights_dashboard_update accepts expectedUpdatedAt, the updatedAt value from insights_dashboard_get. If the dashboard changed since, the update fails with a CONFLICT error instead of overwriting it.

Troubleshooting

The server does not support dynamic client registration. Update your MCP client to a version that supports the current MCP authorization flow, then remove and re-add the server.
The token doesn’t include the scope the tool needs. Reconnect the server and approve the scope listed in the scopes table.
You belong to several organizations and your browser session has ended, so the server can’t tell which organization to use. Sign in to Codemod in the browser, then reconnect the server.
Your client doesn’t support MCP elicitation, and the tool requires confirmation. Run the action in the Codemod app, or use a client that supports elicitation.
The dashboard changed after your assistant read it. Ask the assistant to fetch the dashboard again with insights_dashboard_get and retry the update.
Confirm you approved the matching :write scope and that your role in the active organization allows the action.

Insights

Dashboards and widgets you can read and create through MCP.

Campaigns

Run codemods with automated PRs and centralized tracking.

Codemod Wish

Ask Codemod AI for help inside the platform.

Codemod MCP (CLI)

Local MCP tools for building and testing codemods.